cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
52
Views
0
Helpful
3
Replies

Intune Integration failure

cghaderpour
Level 3
Level 3

Hello,

I encountered a new issue on ISE 3.3 Patch 9.

We have an Intune MDM integration that is used for device (iPads) registration and compliance status checks. After working without any issues for nearly two years, it has suddenly started failing with the following error:

Connection to server failed with:

Failed to acquire auth token from Azure AD.
com.microsoft.aad.msal4j.MsalClientException:
java.net.ConnectException: Connection refused (Connection refused)

Please try with different settings.

Nothing has changed from a certificate perspective. All configuration settings match the Azure App Registration settings.

Does anyone have any idea what could be causing this issue?

I have a Cisco TAC case open, and they suggested importing the Microsoft Graph certificate into the trusted certificates store on ISE. However, I have been unable to find such a certificate, nor can I find any documentation indicating that a Microsoft Graph certificate needs to be imported for Intune integration.

Any guidance would be appreciated.

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

What is the change in the environment? I am sure there is; without that, the working system can not go wrong.

Check some guides :

https://community.cisco.com/t5/security-knowledge-base/cisco-ise-with-microsoft-active-directory-entra-id-and-intune/tac-p/4863274#toc-hId-524178477

https://www.cisco.com/c/en/us/td/docs/security/ise/UEM-MDM-Server-Integration/b_MDM_UEM_Servers_CiscoISE.pdf

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Honestly, nothing has changed. We had some synchronization issues previously, and Cisco Support recommended disabling and re-enabling the MDM integration on ISE. We did that, and the issue was resolved.

A few days later, however, the connection failed completely. The certificates and configuration settings are all in place and appear to be correct.

I researched the error, but I couldn't find any useful information that points to a specific cause.

I would recommend using packet capture (can do this from ISE GUI). There you can see what certificates (FQDN) is beeing exchanged and you can more easily see if all trust chains and trust certs are in place. Something has to have changed there.